Retailers Must Stop Selling Malware-Infected Android Devices
EFF Deeplinks
- Amazon and other major online retailers are urged to implement systemic measures to stop the sale of Android devices pre-installed with malware.
- The "BADBOX" campaign affected 10 million uncertified Android Open Source Project (AOSP) devices, ranging from TV streaming boxes to digital picture frames.
- Compromised devices often use home networks to conduct illegal activities, and malicious actors continue to evolve tactics despite private sector takedowns.
The Scope of the Problem
- Manufacturers often ship custom versions of Android that include hidden, malicious applications.
- These apps frequently lack visible icons, making them nearly impossible for average users to detect.
- Retailers currently handle these threats reactively, often addressing individual reports rather than blocking the supply chain.
Call to Action for Retailers
- Companies like Amazon should leverage their vast anti-fraud resources to proactively identify and block malware-laden hardware.
- Retailers should improve consumer transparency by clearly communicating when similar products are subject to malware-related takedowns.
- The FBI has warned consumers to avoid cheap streaming devices that promise "free" access to premium sports and movie content, as these are common vectors for malware.
Ecosystem Improvements Needed
- Greater emphasis is required on firmware transparency to verify the integrity of pre-installed software.
- Original Equipment Manufacturers (OEMs) must be held accountable for the security of their products.
- Retailers should better educate consumers, particularly during high-traffic shopping events like Prime Day, to help them make informed, safe purchasing decisions.